VulnerabilityModified
CVE-2016-10555
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server.
MEDIUM 6.5EPSS 4.86%
Does this matter?
Lower severity and a low EPSS score (4.86%). Track it; it rarely justifies an emergency change on its own.
Description
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the public key is actually an HMAC private key. This could be used to forge any data an attacker wants.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 4.86% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-310
- Affected
- jwt-simple project/jwt-simple
- Source
- support@hackerone.com
References
- https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/Broken Link, Third Party Advisory
- https://github.com/hokaccha/node-jwt-simple/pull/14Issue Tracking, Third Party Advisory
- https://github.com/hokaccha/node-jwt-simple/pull/16Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/87Third Party Advisory
- https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/Broken Link, Third Party Advisory
- https://github.com/hokaccha/node-jwt-simple/pull/14Issue Tracking, Third Party Advisory
- https://github.com/hokaccha/node-jwt-simple/pull/16Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/87Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.